Annotations
This phish typically originates from a non-Cornell account. The sender may appear as "Cornell|Support|2FA Multifactor <[name]@white.plala.or.jp>". Do not reply to the sender nor scan the QR code. The QR code directs to a fake login page. If you entered your credentials into the page, change your NetID password immediately at https://netid.cornell.edu